NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6329 | CVE-2008-6598 | Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic." | 2 | 10 | High | 2017-01-03 | 2009-04-18 | View | |
| 6330 | CVE-2008-6599 | cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which allows remote attackers to obtain session data via a direct request related to the "default session save path." | 2 | 5 | Medium | 2017-01-03 | 2009-04-18 | View | |
| 48575 | CVE-2009-1288 | Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager. | 2 | 4.3 | Medium | 2017-01-07 | 2009-04-18 | View | |
| 48576 | CVE-2009-1289 | private/login.ssi in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allows remote attackers to discover the access roles and scopes of arbitrary user accounts via a modified WEBINDEX parameter. | 2 | 4 | Medium | 2017-01-07 | 2009-04-18 | View | |
| 48577 | CVE-2009-1290 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the authentication of administrators, as demonstrated by a power-off request to the private/blade_power_action script. | 2 | 6.8 | Medium | 2017-01-07 | 2009-04-18 | View |
Page 3000 of 17672, showing 5 records out of 88360 total, starting on record 14996, ending on 15000